# "private key" (compromised OR stolen OR leaked) — X 热门讨论 (2026-09-19 17:44 UTC)
## @Mklovergurl (Dulzura) · 09-07 20:01 · ♥24 ↻11 💬7 Wallet security is not only about where the private key is stored.
It is also about where cryptographic operations happen, how keys are isolated, and what the user is actually authorizing.
@UN_wallet takes a hardware-based approach to this problem.
The card uses a secure element with EAL6+ security certification, designed to keep sensitive key operations isolated from the software environment interacting with the wallet.
That separation matters because the software layer can be exposed to phishing sites, malicious dApps, compromised extensions, injected scripts, and other forms of attack
The application can construct a transaction. But constructing a transaction is not the same as authorizing it.
Authorization requires a cryptographic signature generated using the private key. The goal of a hardware signing architecture is to keep that key away from the potentially compromised environment while allowing the user to approve the operation.
The use of NFC also changes the interaction model. Instead of relying on a continuously connected device, the physical card becomes part of the authorization process.
The biggest security problem in self-custody isn't always someone stealing a seed phrase. Sometimes, the user simply signs something they didn't fully understand. That's why the future of wallet security isn't just about stronger cryptography. It's about key isolation, controlled signing environments, and making authorization harder to misuse.
The interface is where transactions are requested https://x.com/Mklovergurl/status/2097052561228566681
## @SlowMist_Team (SlowMist) · 09-08 07:16 · ♥17 ↻3 💬3 🚨SlowMist TI Alert🚨
💸 WealthManagementV2 Loss: 26,414 USDT
🔍 Root Cause: The owner privileges of the victimized contract were suspected of being illegally transferred (possibly due to a leaked private key). The new owner (attacker-controlled) can instantly set plan parameters (`period=0`, `interestMultiplier`/`unlockMultiplier=528,300,000`) via `updatePlanConfig` without timelock or bounds. This allows minting inflated interest by investing and redeeming in the same tx, then unlocking and withdrawing it via a second investment.
📌 Attacker: EOA `0xe439422afdd247503f75b4143c4a973eced04a36` 📌 Victim Contract: WealthManagementV2 `0x7b5dda5135811ec0870a75a04d0e1807edc3c93d`
Transaction: https://t.co/g2kiAODRsT https://t.co/PEmc4BbqqY
Powered by https://t.co/Mz5jOnx997 https://x.com/SlowMist_Team/status/2097222515009724817